← Back

Morningstar: full interview with an emerging actor in the pro-Russian hacktivist ecosystem

iQBlack publishes the full interview conducted with Morningstar in March 2026. The material preserves the actor’s direct voice and allows readers to compare its responses with the analytical reading published by iQBlack on April 5 about its role within the pro-Russian hacktivist ecosystem.

Leer en Español
Print Share

On March 31, 2026, iQBlack conducted a direct interview with Morningstar, an actor that was then emerging within the pro-Russian hacktivist ecosystem and focused, according to its own description, on “intelligent systems and devices”. Today, Morningstar presents itself as part of Z-Alliance/Z-Pentest Alliance, in a transition the actor itself describes as a full merger between teams with shared interests, motivation, and common goals.

Based on those responses, on April 5, 2026, iQBlack published an analytical piece titled Morningstar: what an emerging and active actor reveals about the pro-Russian hacktivist ecosystem. That analysis was not intended to reproduce the interview in a linear way, but to interpret what the responses revealed about Morningstar’s position inside an ecosystem where political identity, actor collaboration, access to exposed systems, information circulation, and the search for legitimacy overlap.

iQBlack publishes intelligence and threat analysis from another perspective. For that reason, this publication serves a different purpose. Here, the full interview is presented as primary material, as a direct source of the actor’s self-description, and in its original version. The objective is to allow researchers, analysts, journalists, security teams, and specialized readers to access the actor’s responses directly and compare them with iQBlack’s previously published analytical reading, or draw their own conclusions.


Editorial note on the literal publication

Morningstar’s responses are presented literally, with minimal formatting normalization to improve readability. The publication of these responses does not imply that iQBlack validates every statement made by the actor. In some passages, the actor uses derogatory language to refer to certain analysts. iQBlack decided to preserve those expressions because they are part of the interview’s documentary value.


The actor’s voice as a starting point

What follows is Morningstar’s direct voice, without an interleaved reading by iQBlack between questions and answers.


  • Within the broader pro - Russian ecosystem, how would you describe Morningstar's role today?
Interesting question. We still consider ourselves newcomers in this ecosystem. Broadly speaking, our role is to focus on what we do best - hacking intelligent systems and devices. We are not limited to any specific type of technology, whether it's cameras or control panels. Some of the information we obtain is shared with our friends and colleagues, thus participating in data exchange within the community.

  • When people outside that space try to categorize Morningstar, what do they usually misunderstand?

To be honest, outsiders usually seriously underestimate how much effort goes into hacking. It's not nearly as simple as articles about Shodan and similar tools make it seem. We have our own tools, we don't just rely on simple password guessing, and we use a variety of methods, often combining different approaches.

Honestly, it even makes us laugh when we see people write things like, "It's just Shodan, I can do the same in five minutes." Sure... try it yourself, and then tell us how fast it really went. In reality, it's much more complicated and requires time, patience, and experience.

  • What makes some aligned actors operationally useful while others remain mostly symbolic?

It's primarily about the team - when people are truly passionate about what they do and do it well, they become genuinely valuable from an operational standpoint. They're driven by the task and execute it elegantly.

On the other hand, misunderstandings sometimes arise between teams, and there are groups that exist mainly for PR. Such teams appear, create the illusion of activity, and then disappear just as quickly, without making any significant contribution to the overall work.

  •  In your view, what separates a real collaborative ecosystem from several actors simply moving in the same direction at the same time?

Hmm... Actually, the difference is quite simple. A real collaborative ecosystem is when teams work seamlessly and complement each other. For example, you can look at the alliance between NoName057(16) and Z-Pentest Alliance: they always operate in sync. Some cause damage through DDoS attacks, while others simultaneously gather data or hack systems.

Moreover, we've known the people from Z-Pentest Alliance for a long time - practically since their founding. They're like an older brother to us: they guide us, show the best ways to act, and we always support them in any operation.

In contrast, the rest operate in a fragmented way: they attack random targets and create the illusion of activity. Some groups even invite high - profile players just for PR, but in reality, it's just noise and endless requests to "repost" their content. There was even a case where a group was forced to repost content in other channels under threat of exclusion - put simply.

The main coalition of Russian hackers already communicates effectively among themselves; they don't need groups for reposts or similar things. They act in a coordinated and disciplined manner.

  • Do durable relationships in this space tend to form around trust, technical capability, access, or shared narratives?

In this environment, lasting relationships are primarily built on trust, mutual understanding, and a shared goal. Technical capabilities are, of course, important, but they don't determine the strength of the bonds. If groups share a common vision and follow it, nothing can stop them. Technical resources can always be scaled up, but convincing someone to adopt another's idea - that's an entirely different story.

  •  When coordination happens across different actors, what usually drives it most: timing, target relevance, shared tooling, or public messaging?

Most of the time, coordination is driven by PR - many people want to catch a moment of fame, if you can call it that.

We've been lucky in this regard: we know the people from Z-Pentest Alliance, who supported us during our early stages. We never refuse them help and throw all our efforts in whenever they need something.

We're also somewhat familiar with the folks from NoName057(16) - we like what they do and hope that one day we can reach their level.

And, of course, there's collaboration with PalachPro. He can be a bit tricky at times, but we like him.

By the way, hi to Palachulka if you're reading this!

  •  Some observers see names like APT Babushka, PalachPro, or Z-Pentest Alliance as part of overlapping circles. From your perspective, is that overlap operational, social, or just perceptual?

Hmm... We have alliances with all three groups, so there's overlap in our work. We've known the people from Z-Pentest Alliance for a couple of years now, and our relationship is almost like family. APT Babushka - we could say they're like our Spanish brother, if I may. And PalachPro... well, who doesn't like him?

All of these groups share common ideals they strive toward. Additionally, we maintain good communication, which makes the overlap not just operational but also social: there are both professional connections and friendly relationships.

  •  How important are support assets or companion resources around a core actor, whether for amplification, scouting, validation, or narrative control?

When it comes to key players, in Russia we would highlight NoName057(16), Z-Pentest Alliance, and PalachPro.

Around such groups, supporting resources and allies play an important role. If they need help with a particular operation, it makes sense for other teams to temporarily set aside their own tasks and contribute to the shared goal - this amplifies the effect and produces more noticeable results.

On our side, we try to support all the groups we are allied with and never refuse help. It's precisely through this mutual assistance that a strong ecosystem is built.

  •  What kind of contribution tends to be more valuable in practice: executing actions, identifying targets, validating claims, or shaping public perception?

In practice, what matters most to us is achieving the goal itself. Everything else - identifying objectives, validation, or shaping public perception - takes a back seat.

At the same time, the issue of validation can often be controversial: the same situation can be presented differently in the media. That's why it's important for us that the audience sees what's actually happening, not just the version portrayed by EU politicians and the media.

  •  When a group or persona becomes too visible, does that usually strengthen cooperation opportunities or make trust harder?

Neither, really. When a group becomes more media - visible, security becomes the primary concern.

For example, we observed the so - called Operation Eastwood, which was portrayed as a successful strike against NoName057(16). In practice, it was quite the opposite - the team didn't disappear; on the contrary, they came back stronger and continued their activities.

Overall, media exposure is a double - edged sword. On one hand, it can open up new opportunities; on the other, it significantly complicates trust. The more visible you are, the more people there are around who might be looking either for PR at your expense or access to your information.

  •  What kinds of mistakes reveal that two actors who appear aligned are not actually coordinating?

You can usually tell by some rather basic things - primarily, the lack of proper communication between teams. If there's no coordination, everyone starts acting on their own. It's like in sports: if the team isn't synchronized, there won't be any results - everyone plays their own game, and the overall plan simply doesn't come together.

At the same time, disunity isn't always entirely bad. In some situations, it can even be an advantage: one group distracts attention, while another operates where it's least expected.

  •  From your perspective, what signs indicate that an outside analyst is mistaking ideological proximity for operational linkage?

Like everyone else, we read the news and look at the bold statements of invited analysts - and honestly, it often looks like a circus. You can even take our example (and it's far from the only one): first, they announce a "hack," and then they backtrack, claiming it could have been just someone with a phone taking a photo to scare someone.

These situations reveal the main sign of a mistake: the analyst doesn't understand what's happening in practice and starts making up theories on the fly. Today one thing, tomorrow another - anything just to explain what's going on.

It feels like many of them are just sitting in their positions and not doing anything real for which they are paid. This is especially clear with those invited to the media for comments and "breakdowns" - lots of loud words, but little understanding of the essence.

Honestly, if it were up to us, we'd label such "analysts" as IDIOTS.


Editorial closing note

This interview is published as a documentary record of a direct interaction with Morningstar. Its reading allows the actor’s self-description to be compared with its public activity, with the analysis published by iQBlack on April 5, 2026, and with the subsequent evolution of the pro-Russian hacktivist ecosystem, including its declared integration into Z-Alliance/Z-Pentest Alliance.

This publication also reflects part of the work iQBlack develops through [Cyber]Crime Characterization for Intelligence (3C-INT), where actors such as Morningstar are observed, characterized, and linked within a broader ecosystem of relationships, public activity, and intelligence signals. The full content of that characterization remains reserved for private and contractual workflows; only the editorial material suitable for public consultation is published here.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved